2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31321CRITICAL9.1The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform ...
CVE-2022-31190MEDIUM5.3DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui...
CVE-2022-31188CRITICAL9.8CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were foun...
CVE-2022-31186LOW3.3NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulner...
CVE-2022-31185MEDIUM5.3mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, eve...
CVE-2022-31184HIGH7.5Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to sen...
CVE-2022-31183CRITICAL9.8fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on N...
CVE-2022-31182MEDIUM5.3Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static asset...
CVE-2022-31181CRITICAL9.8PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to ...
CVE-2022-31180CRITICAL9.8Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of ...
CVE-2022-31179CRITICAL9.8Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injec...
CVE-2022-31178MEDIUM4.3eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged i...
CVE-2022-31177LOW2.7Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4....
CVE-2022-31173HIGH7.5Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resu...
CVE-2022-31155MEDIUM4.3Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible fo...
CVE-2022-31154MEDIUM4.3Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to ...
CVE-2022-31148MEDIUM5.4Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerabi...
CVE-2022-31128MEDIUM5.4Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi...
CVE-2022-31109MEDIUM6.1laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP messa...
CVE-2022-34307MEDIUM4.3IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to ...
CVE-2022-34164MEDIUM5.5IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X...
CVE-2022-34163MEDIUM6.1IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. Thi...
CVE-2022-34162MEDIUM6.1IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi...
CVE-2022-34161HIGH8.8IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2022-33955MEDIUM6.8IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code due using a back and r...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now